Vulnerability record · CVE-2024-2054 · published 21 March 2024
CVE-2024-2054: Artica Proxy unauthenticated PHP object deserialization leads to code execution
AArticatech · Artica Proxy
Artica-Proxy's administrative web application deserializes arbitrary PHP objects supplied by unauthenticated users, which then allows code execution as the www-data user. Because the flaw is reachable without credentials and requires no user interaction, it exposes the proxy's web interface to remote compromise. The record does not list affected versions or fixed releases.
Description
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, public exploit references and a 99.6th percentile EPSS probability make this an urgent exposure despite no KEV listing.
What it is
Artica-Proxy's administrative web application deserializes arbitrary PHP objects supplied by unauthenticated users, which then allows code execution as the www-data user. Because the flaw is reachable without credentials and requires no user interaction, it exposes the proxy's web interface to remote compromise. The record does not list affected versions or fixed releases.
Impact
An attacker can run arbitrary code as the www-data user on the Artica-Proxy host, giving full control of the web application context and a foothold for further compromise. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through the Artica-Proxy administrative web application; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. The description confirms the malicious PHP objects are supplied by unauthenticated users.
Exploitation
CISA KEV does not list this CVE, but public exploit references are present (Exploit-tagged Full Disclosure and KoreLogic advisory), and EPSS is very high at 0.8126 (99.6th percentile), indicating likely active exploitation attempts.
What to do
- Apply the vendor fix for Artica-Proxy as soon as a patched release is available; the record does not name a fixed version, so confirm with the vendor.
- Restrict network access to the Artica-Proxy administrative web interface to trusted management networks or VPN only.
- If patching is not immediately possible, take the administrative interface offline or place it behind an authenticating reverse proxy.
- Run the Artica-Proxy service under a least-privilege account and review file permissions for the www-data user.
- Monitor vendor and KoreLogic advisories for updated guidance and fixed versions.
Detection
- Inspect web server and Artica-Proxy logs for POST requests to administrative endpoints containing serialized PHP object payloads (for example O: or a: patterns) from unauthenticated clients.
- Alert on unexpected child processes or command execution spawned by the www-data user or the Artica-Proxy web process.
- Monitor for outbound connections or file writes originating from the Artica-Proxy host that are inconsistent with normal proxy behavior.
- Review access logs for scanning or exploitation attempts against the administrative interface from untrusted source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2024/Mar/12 | ExploitMailing List |
| https://korelogic.com/Resources/Advisories/KL-001-2024-002.txt | ExploitThird Party Advisory |
| http://seclists.org/fulldisclosure/2024/Mar/12 | ExploitMailing List |
| https://korelogic.com/Resources/Advisories/KL-001-2024-002.txt | ExploitThird Party Advisory |
Track CVE-2024-2054 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-2054), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.